Compliance-Driven Penetration Testing
Penetration testing for SOC 2, HIPAA, and cyber insurance
Scanners find missing patches. A real test finds the way in. We test your network the way an attacker would, then hand you the dated, auditor-ready report your framework or cyber insurance carrier asks for, with a fix list ranked by what an attacker could actually use. Published pricing from $4,000.
Aligned to PCI DSS, HIPAA, SOC 2, and NIST CSF requirements.
Most businesses do not find out where they are exposed until someone else does. A vulnerability scan tells you what software is out of date. It does not tell you whether an attacker can actually chain those gaps together to reach your patient records, your client files, or your bank.
A penetration test answers the question scanners cannot: if someone wanted in, could they get in, and how far would they get? We test the way a real attacker would, then we sit down and tell you the truth about what we found and what to fix first.
What we test
External
Everything you expose to the internet: firewall, VPN, email, web servers. What an outsider could reach without setting foot in your building.
Internal
What happens after someone is already inside. We simulate a compromised laptop and find the flat networks, over-shared drives, and the path to your domain controller.
Web application
Logins, payment flows, file uploads, and APIs, probed for the real flaws automated scanners miss, written up so your developers can act on them.
Phishing & social engineering
A controlled campaign that shows who clicks, who reports, and what one stolen set of credentials could unlock. The point is to know where training should go.
Do you actually need a penetration test?
Usually the answer arrives as a requirement: a SOC 2 audit, a HIPAA risk analysis, a PCI deadline, or a cyber insurance renewal questionnaire. We scope the test to the standard you answer to, so the report does double duty as compliance evidence instead of sitting in a drawer.
SOC 2
Auditors expect evidence that you actively test for exploitable weakness. A dated report mapped to your Trust Services Criteria is the clean way to show it.
HIPAA
A pentest is one of the strongest forms of the Security Rule evaluation, proving whether someone could actually reach electronic PHI, not just that a policy exists.
PCI DSS
Requirement 11.3 calls for internal and external penetration testing at least annually and after significant change. We scope to it directly.
Cyber insurance
Carriers increasingly ask for a recent test on the renewal questionnaire. We hand you a report that answers the question and a fix list to close gaps before the deadline.
Working toward a specific standard? Start with compliance readiness, and see how testing fits our broader managed cybersecurity.
How we test, and what you get back
Comprehensive by design, so the assessment is complete and the report is something your team can actually act on.
Real-world attack simulation
We replicate the tactics, techniques, and procedures actual attackers use, then validate exploitability by hand. The point is to find the chained, real paths into your environment, then show you exactly how to close them.
Detailed, actionable reporting
Every engagement ends in a clear report: an executive summary for leadership, technical detail for your engineers, and step-by-step remediation for each finding, ranked by exploitability so your team knows exactly what to fix first.
Customizable scope
No two organizations are the same. We tailor every engagement to your environment, your concerns, and the compliance you answer to, so the test covers what actually matters to your business.
Four steps. No jargon. No drama
A penetration test should leave you clearer, not more confused. Here is exactly how an engagement runs from first call to retest.
- 01
Scope
A short call to agree exactly what we test, when, and the rules of engagement. Everything is in writing before anything starts.
- 02
Test
Automated tooling plus real hands-on testing, looking for what an attacker could actually use, not a list of theoretical findings.
- 03
Report
A clear report in plain English: what we found, how serious it is, and the proof, with a prioritized fix list your team can actually act on.
- 04
Retest
You fix the findings, we retest them, included. You should not pay twice to confirm a fix actually worked.
Transparent, published pricing
Starting prices, published up front. Your final quote is fixed and in writing after a 30-minute scoping call.
Small External Pentest
External-only test for small environments
$4,000 from
- Up to 50 external IPs or one primary domain
- Authenticated and unauthenticated testing of public-facing services
- A written report ranking every finding by exploitability
- 30-day retest of fixed findings, included
Best for: Single-location SMBs and compliance-driven first-time tests
Get this quoteMedium Full Pentest
External plus internal network assessment
$6,500 from
- Up to 100 external IPs and up to 250 internal hosts
- Active Directory enumeration and privilege-escalation testing
- Executive summary, technical findings, and a remediation roadmap
- 30-day retest of fixed findings, included
Best for: HIPAA or PCI scoped environments and second-engagement clients
Get this quoteLarge Enterprise Pentest
Full scope: external, internal, web app, and phishing
$10,000 from
- Unlimited external IPs and up to 1,000 internal hosts
- Web application testing and a phishing simulation (50-user sample)
- Active Directory enumeration with lateral-movement testing
- Executive briefing call, plus a 60-day retest of fixed findings
Best for: Multi-location businesses and SOC 2 audit prep
Get this quoteTesting in a regulated field? We frequently scope to HIPAA, PCI, and SOC 2 requirements. Run a dental practice? See dental IT and security. Specialized engagements also run through our dedicated Arizona penetration testing practice, azpentest.
Why businesses pick us over other pentest firms
The four things buyers tell us made the difference.
Real attacker methodology
A real penetration test goes well beyond an automated scan. We use the same tools and techniques real attackers use, then confirm exploitability by hand, so findings are ranked by what an attacker can actually exploit.
Reports your team can action
Executive summary for the board, technical findings for your engineers, and a specific fix tied to every issue, ranked by exploitability. Your team knows exactly what to address first.
Compliance built in
Every engagement is aligned to PCI DSS, HIPAA, SOC 2, and NIST CSF. Findings map to specific controls where relevant, and the report format is one your auditor will accept without revisions.
Retest included, not an upsell
A retest of fixed findings is built into every engagement and included in the price, 30 days on Small and Medium, 60 on Enterprise. You verify the gaps are closed before the report is final.
Frequently asked questions
What businesses ask before booking a test.
Do I need a penetration test for SOC 2?
In practice, yes. SOC 2 does not name a penetration test in a single line, but auditors expect evidence that you actively look for exploitable weaknesses, and a dated pentest report is the cleanest way to show it. We scope the test to the Trust Services Criteria in your audit and write the report so it drops straight into your evidence binder.
Does a penetration test meet HIPAA requirements?
HIPAA requires a Security Rule risk analysis and ongoing evaluation. A penetration test is one of the strongest forms of that evaluation: it shows whether someone could actually reach electronic Protected Health Information, not just whether a policy exists on paper. We map findings to the relevant safeguards so your documentation holds up.
How much does a penetration test cost?
Transparent, published starting prices: external testing from $4,000, external-plus-internal from $6,500, and a full-scope engagement (external, internal, web app, and phishing) from $10,000. The final number depends on the size of your environment and what is in scope. A retest of fixed findings is included in every tier.
Will this satisfy our cyber insurance requirement?
Yes. We produce a clean, dated penetration test report that answers what carriers ask on their questionnaires, plus a prioritized fix list so you can close gaps before renewal.
Is this an automated scan or a real manual penetration test?
Both. Every engagement is an automated pass plus hands-on manual testing by a human. Manual testing is where the chained, real-world attack paths get found, the ones an automated scanner alone will miss.
Is a retest included after we fix the findings?
Yes. Every tier includes a retest of your fixed findings, 30 days on the smaller tiers and 60 days on the enterprise tier.
Do we have to be a managed IT client?
No. Penetration testing is a standalone engagement. We test plenty of environments managed by an in-house team or another provider, and we write the report so your team can act on it.
Find out what is actually exposed
Tell us what is prompting the test, an insurance renewal, a client requirement, or just wanting to know where you stand. We come back with a scope and a fair, fixed quote.
Call (855) 737-9500 / (480) 573-3349
Email [email protected]
15-minute response on critical issues, 24/7. Onboarding in two to three weeks.